Live data from Hacker News

Briar: Peer-to-Peer Encrypted Messaging

briarproject.org

121–130 of 145 posts

Re: Briar: Peer-to-Peer Encrypted Messaging

#121

Earlier quoted context omitted.

Interesting - the Java version runs on Windows[0][1]! I suppose I'll check it out, then. [0]: if you drop a dependency into the jar - https://github.com/JetBrains/skiko/releases/download/v0.7.40... (you want the DLL, the checksum, and the .dat) [1]: https://cdn.upload.systems/uploads/RC0uthIY.png

Are you able to get messaging working on Windows? Their website says they only support linux currently.

Well, it's a Java app. It just works everywhere.

I was able to create an account just fine, though I don't have any contacts to message. I don't have any reason to believe it wouldn't work fine, though.

Re: Briar: Peer-to-Peer Encrypted Messaging

#122

Just wanna say this app saved my family and I when we went on a cruise. Normally, we would had had to pay to use the chat service via the ship's paid-only Wi-Fi (since we get no phone reception on the seas). Without needing to pay for the Wi-Fi, we were all able to use Briar to communicate whilst connected to the network, which made coordinating and finding each other on the ship way easier. It was great and worked r…

I'm a bit torn about this. On one hand, it definitely makes coordinating things last minute easier on a cruise ship. On the other hand, to me being nearly forced to untether is most of the reason for going on a cruise, so still carrying my phone around with me even if only to message family is partially missing the point! Maybe I'll feel different with kids on a cruise ship, but honestly I enjoyed the freedom of spen…

Definitely depends on the size of your party. We were a group of five, split between three cabins on different floors of the ship. With how tremendously huge modern cruise liners are and how crowded cruises can be, I found it was invaluable. For example, being able to quickly message "I went back to the cabin" or "I'm on deck 6 at the table at the far back" or "meet you at the dining hall at 5pm" was very helpful.

Re: Briar: Peer-to-Peer Encrypted Messaging

#123

Just wanna say this app saved my family and I when we went on a cruise. Normally, we would had had to pay to use the chat service via the ship's paid-only Wi-Fi (since we get no phone reception on the seas). Without needing to pay for the Wi-Fi, we were all able to use Briar to communicate whilst connected to the network, which made coordinating and finding each other on the ship way easier. It was great and worked r…

I miss the days of mystery and adventure as a child, of being totally disconnected and unfindable, and lost without fear.

That's cool and and me too, but I don't see how that relates to my use-case. None of us were lost or in fear or un-findable without Briar, it just made the trip more convenient for coordinating time and place between multiple parties.

Re: Briar: Peer-to-Peer Encrypted Messaging

#124
post #55

Earlier quoted context omitted.

>iOS, which is superior for digital privacy False dichotomy. GrapheneOS, LineageOS, you have options on (some) Android handsets. You have no options on iOS. Further, much of Apple's walled-garden ecosystem is closed source. Apple is HORRIBLE for user privacy, only marginally less horrible than Google. The difference is that Google isn't a tyrant who insists on making devices that MUST run their own OS. Ironically, Pi…

>GrapheneOS, LineageOS, you have options on (some) Android handsets These are not normal approaches used by the common person. Apple is not horrible for privacy, they simply help prevent certain types of surveillance capitalism.

Apple absolutely is horrible for privacy. To insist otherwise suggests you might either be uninformed, willfully ignorant, falling victim to Apple's sham marketing around privacy, experiencing stockholm syndrome, or an apple employee.

Examples include: - Apple surreptitiously recording conversations without user consent (https://www.politico.eu/wp-content/uploads/2020/05/Public-St...) - Apple approving apps in the app store that have libraries ostensibly singly focused on the violation of privacy, complete with behavior that would be expected from those with suspicious or questionable motives, like uploading in the middle of the night (https://www.oregonlive.com/opinion/2019/05/its-3-am-do-you-k...) - Misleading users into thinking that their wifi and bluetooth may be disabled when they actually aren't - a UI control that merely disconnects the radios from APs / remote devices, rather than turning the radios off (https://www.theguardian.com/technology/2017/sep/21/ios-11-ap...) - iPhones send a ton of data (including call logs) to Apple servers, which participated in the illegal PRISM mass surveillance scandal, and conceivably report to similar secret programs that the public is not aware of to this day (https://theintercept.com/2016/11/17/iphones-secretly-send-ca...) - iMessage reports back to Apple every phone number you've ever entered into it, data that Apple probably shares with law enforcement (https://theintercept.com/2016/09/28/apple-logs-your-imessage...) - iCloud is enabled by default. All of your pictures, videos, documents, etc are NSA-accessible, but also rendered vulnerable to anyone with your credentials. This was the root cause of the celebrity nude photo leaks several years ago. - Mac computers had routinely sent files stored on encrypted disks to Apple servers without user permission ever being prompted for or granted (https://www.theguardian.com/technology/2014/nov/04/apple-dat...) - Here's a great analysis of all the snooping Apple did on Yosemite with all privacy features enabled (https://github.com/fix-macosx/yosemite-phone-home) - More various articles (https://arstechnica.com/gadgets/2014/05/new-guidelines-outli...), (https://www.theguardian.com/technology/2014/jul/23/iphone-ba...), (https://finance.yahoo.com/blogs/the-exchange/privacy-advocat...).

And these are just privacy concerns. This doesn't even begin to delve into the realms of DRM, downgrade prevention, planned obsolescence, dark patterns, censorship, or open collaboration with inhumane, authoritarian regimes.

Re: Briar: Peer-to-Peer Encrypted Messaging

#127
post #55

Earlier quoted context omitted.

>GrapheneOS, LineageOS, you have options on (some) Android handsets These are not normal approaches used by the common person. Apple is not horrible for privacy, they simply help prevent certain types of surveillance capitalism.

Apple absolutely is horrible for privacy. To insist otherwise suggests you might either be uninformed, willfully ignorant, falling victim to Apple's sham marketing around privacy, experiencing stockholm syndrome, or an apple employee. Examples include: - Apple surreptitiously recording conversations without user consent ( https://www.politico.eu/wp-content/uploads/2020/05/Public-St... ) - Apple approving apps in the…

>To insist otherwise suggests you might either be uninformed, willfully ignorant, falling victim to Apple's sham marketing around privacy, experiencing stockholm syndrome, or an apple employee.

No, it means I'm optimizing for the average user who will not go out of their way to LARP a paranoid opsec level.

Re: Briar: Peer-to-Peer Encrypted Messaging

#129

Earlier quoted context omitted.

Apple absolutely is horrible for privacy. To insist otherwise suggests you might either be uninformed, willfully ignorant, falling victim to Apple's sham marketing around privacy, experiencing stockholm syndrome, or an apple employee. Examples include: - Apple surreptitiously recording conversations without user consent ( https://www.politico.eu/wp-content/uploads/2020/05/Public-St... ) - Apple approving apps in the…

>To insist otherwise suggests you might either be uninformed, willfully ignorant, falling victim to Apple's sham marketing around privacy, experiencing stockholm syndrome, or an apple employee. No, it means I'm optimizing for the average user who will not go out of their way to LARP a paranoid opsec level.

The average user's probably got their SSN, DoB, address, full name, employment history, credit card track 2's, passport details, and more spread across multiple breaches, being sold across multiple darkweb markets, precisely because they have zero regard for privacy.

Suggesting that usage of GrapheneOS is "LARP"ing a "paranoid" opsec level is dismissive of the very-real threats facing domestic abuse victims, whistleblowers, journalists & political activists/dissidents in repressive, authoritarian regimes, and countless others.

Just because you live in a safe, privacy-respecting, liberal democracy doesn't mean everyone else does, and it absolutely isn't reasonable justification to demean those who don't by painting them as irrationally paranoid. That's gaslighting real victims who actually have to be concerned about these companies handing out their data to countries that will put them through, in extreme cases, excruciating torture, before killing them or imprisoning them for life.

Not everyone is lucky enough to live your life, so stop assuming your threat model is automatically the "right" one for everyone else, and that any more intensive threat models than yours are inherently "irrational", "unrealistic", or "paranoid".

Re: Briar: Peer-to-Peer Encrypted Messaging

#130
post #38
post #14

Earlier quoted context omitted.

The directory services are the equivalent of DNS. The role of Tor is it facilitates anonymous, end-to-end encrypted connection between client and server, each messaging app is both a client (or a set of clients) and a server (a Tor Onion Service) that talk to each other through the Tor network. This way the traffic never exists the Tor network*. Tor Project has an excellent new article about Onion Services at https:/…

I understand, but the server (dns like) still knows everything which is not good imho

The directory service only receives an anonymous notification behind Tor proxyt chain that "hey, if someone asks for this .onion URL, point them to this node as it can provide further directions". It doesn't know "everything". The point of Tor has been from the beginning to compartmentalize what each node knows the the bare minimum.
Post reply on HN